Solved! Use WFTHSERV32.DLL (Trojan Downloader) Removal Guide

I recommend you UnHackMe - Ultimate Malware Killer for fast malware removal:

Free Download
Fully Functional 30-day Trial. No credit card is required.
Reviews
. EULA. Privacy Policy. Uninstall.

WFTHSERV32.DLL – Trojan Downloader removal

FileMD5Virus Alias
WFTHSERV32.DLL 2ff3614f69dfae08eb8711e73c97b48d Trojan Downloader
WFTHSERV32.DLL 2ff3614f69dfae08eb8711e73c97b48d Trojan SuspiciousFile
WFTHSERV32.DLL 2ff3614f69dfae08eb8711e73c97b48d Trojan Generic
WFTHSERV32.DLL 2ff3614f69dfae08eb8711e73c97b48d Trojan Agent
WFTHSERV32.DLL 2ff3614f69dfae08eb8711e73c97b48d Trojan Banload

WFTHSERV32.DLL size: 13824 bytes
WFTHSERV32.DLL hash: 2FF3614F69DFAE08EB8711E73C97B48D

Created files:

%SysDir%\wfthserv32.dll

Autostart registry keys:

HKLM\System\CurrentControlSet\Services\wfthserv\Type: 10000000
HKLM\System\CurrentControlSet\Services\wfthserv\Start: 02000000
HKLM\System\CurrentControlSet\Services\wfthserv\ErrorControl: 01000000
HKLM\System\CurrentControlSet\Services\wfthserv\DisplayName: WIFI Support Service
HKLM\System\CurrentControlSet\Services\wfthserv\ImagePath: 2500530079007300740065006D0052006F006F00740025005C00730079007300740065006D00330032005C0073007600630068006F007300740020002D006B002000770066007400680073006500720076000000
HKLM\System\CurrentControlSet\Services\wfthserv\Description: WIFI Support Service
HKLM\System\CurrentControlSet\Services\wfthserv\Group: Com Infrastructure
HKLM\System\CurrentControlSet\Services\wfthserv\ObjectName: LocalSystem
HKLM\System\CurrentControlSet\Services\wfthserv\FailureAction: 00000000000000000000000001000000000000000200000060EA0000
HKLM\System\CurrentControlSet\Services\wfthserv\Parameters\ServiceDll: 43003A005C00570049004E0044004F00570053005C00730079007300740065006D00330032005C0077006600740068007300650072007600330032002E0064006C006C000000

Detected by UnHackMe:

WFTHSERV32.DLL
Default location: %SYSDIR%\WFTHSERV32.DLL

Dropper information:
MD5: 3b0cbb8b59be57f1141c8fd243c27646
File size: 22528 bytes

Leave a Reply